CVE-2009-0025

BIND <9.6.0 - RCE

Title source: llm

Description

BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

References (33)

... and 13 more

Scores

EPSS 0.0096
EPSS Percentile 76.3%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
... and 35 more

Timeline

Published Jan 07, 2009
Tracked Since Feb 18, 2026